[2008/06/02 18:59:32 | 000,017,098 | ---- | C] () -- C:\Program Files\Common Files\ynyro.scr
[2008/06/02 18:59:32 | 000,016,029 | ---- | C] () -- C:\Program Files\Common Files\widar.bat
[2008/06/02 18:59:32 | 000,014,650 | ---- | C] () -- C:\Program Files\Common Files\qexykidu.sys
[2008/06/02 18:59:32 | 000,013,852 | ---- | C] () -- C:\WINDOWS\ytatuh.sys
[2008/06/02 18:59:32 | 000,013,094 | ---- | C] () -- C:\Program Files\Common Files\mutetidid.sys
[2008/06/02 18:59:32 | 000,012,227 | ---- | C] () -- C:\Documents and Settings\ISAIAH\Local Settings\Application Data\eqagilok.com
[2008/06/02 18:59:32 | 000,012,151 | ---- | C] () -- C:\WINDOWS\anajubude.dll
[2008/06/02 18:59:32 | 000,010,463 | ---- | C] () -- C:\Documents and Settings\ISAIAH\Application Data\aponaqyno._sy
[2008/04/06 20:03:30 | 000,751,830 | -HS- | C] () -- C:\WINDOWS\System32\wrsgmnak.ini
[2008/04/05 20:02:47 | 000,708,827 | -HS- | C] () -- C:\WINDOWS\System32\bibjyfgv.ini
[2008/04/03 20:32:43 | 000,693,426 | -HS- | C] () -- C:\WINDOWS\System32\aktlordj.ini
[2008/04/02 20:31:45 | 000,000,872 | -HS- | C] () -- C:\WINDOWS\System32\llyvdkeu.ini
[2008/04/01 20:30:26 | 001,926,046 | -HS- | C] () -- C:\WINDOWS\System32\hjbvkiou.ini
[2008/03/31 17:34:19 | 001,264,929 | -HS- | C] () -- C:\WINDOWS\System32\mjoleakv.ini
[2008/03/30 09:40:39 | 001,189,162 | -HS- | C] () -- C:\WINDOWS\System32\erwrnott.ini
[2008/03/28 20:26:41 | 001,244,553 | -HS- | C] () -- C:\WINDOWS\System32\gafwxjox.ini
[2008/03/27 20:28:00 | 001,238,104 | -HS- | C] () -- C:\WINDOWS\System32\bhiayjvo.ini
[2008/03/26 20:41:01 | 001,237,984 | -HS- | C] () -- C:\WINDOWS\System32\pbfdocae.ini
[2008/03/25 19:59:08 | 001,419,428 | -HS- | C] () -- C:\WINDOWS\System32\xnsijdbw.ini
[2008/03/25 19:43:21 | 001,473,920 | -HS- | C] () -- C:\WINDOWS\System32\hwbemffm.ini
[2008/03/24 19:38:19 | 001,566,519 | -HS- | C] () -- C:\WINDOWS\System32\ywpmijcw.ini
[2008/03/23 19:44:37 | 001,493,091 | -HS- | C] () -- C:\WINDOWS\System32\oewbetkc.ini
[2008/03/23 17:14:37 | 001,605,203 | -HS- | C] () -- C:\WINDOWS\System32\xqqxsgtl.ini
[2008/03/22 17:11:38 | 001,605,143 | -HS- | C] () -- C:\WINDOWS\System32\qwpditvp.ini
[2008/03/21 17:09:48 | 001,605,083 | -HS- | C] () -- C:\WINDOWS\System32\jrwspefa.ini
[2008/03/19 19:18:54 | 001,604,843 | -HS- | C] () -- C:\WINDOWS\System32\hxuaywho.ini
[2008/03/19 19:12:46 | 000,358,990 | -HS- | C] () -- C:\WINDOWS\System32\qtutv.ini2
[2008/03/19 19:12:45 | 000,358,990 | -HS- | C] () -- C:\WINDOWS\System32\qtutv.ini
[2008/03/19 18:48:49 | 000,000,035 | ---- | C] () -- C:\WINDOWS\Blink.ini
[2008/03/14 18:13:36 | 001,604,543 | -HS- | C] () -- C:\WINDOWS\System32\oabyvkil.ini
[2008/03/13 16:44:02 | 000,950,349 | -HS- | C] () -- C:\WINDOWS\System32\omylvsue.ini
[2008/03/12 19:24:03 | 000,833,340 | -HS- | C] () -- C:\WINDOWS\System32\xqavynef.ini
[2008/03/11 18:35:10 | 000,852,472 | -HS- | C] () -- C:\WINDOWS\System32\yskmnema.ini
[2008/03/10 18:22:20 | 000,881,799 | -HS- | C] () -- C:\WINDOWS\System32\rnbkucmc.ini
[2008/03/09 08:36:54 | 000,938,203 | -HS- | C] () -- C:\WINDOWS\System32\qyylyieu.ini
[2008/03/08 17:50:18 | 000,870,157 | -HS- | C] () -- C:\WINDOWS\System32\biapudhi.ini
[2008/03/07 17:47:17 | 000,870,299 | -HS- | C] () -- C:\WINDOWS\System32\snktbkmi.ini
[2008/03/06 20:21:38 | 000,874,946 | -HS- | C] () -- C:\WINDOWS\System32\gfwtjbac.ini
[2008/03/05 18:07:24 | 000,904,635 | -HS- | C] () -- C:\WINDOWS\System32\dhbouiot.ini
[2008/03/04 18:11:32 | 000,937,960 | -HS- | C] () -- C:\WINDOWS\System32\bfcxidcf.ini
[2008/03/03 18:48:09 | 000,932,674 | -HS- | C] () -- C:\WINDOWS\System32\ngvqbyrf.ini
[2008/03/01 14:04:39 | 001,035,882 | -HS- | C] () -- C:\WINDOWS\System32\otgmcvei.ini
[2008/02/29 20:14:52 | 000,952,965 | -HS- | C] () -- C:\WINDOWS\System32\fqnfcyqb.ini
[2008/02/29 18:36:05 | 001,054,031 | -HS- | C] () -- C:\WINDOWS\System32\qyavbewr.ini
[2008/02/28 18:35:36 | 000,936,828 | -HS- | C] () -- C:\WINDOWS\System32\spannrky.ini
[2008/02/27 18:07:13 | 000,948,660 | -HS- | C] () -- C:\WINDOWS\System32\lqncmiie.ini
[2008/02/26 18:10:02 | 000,935,000 | -HS- | C] () -- C:\WINDOWS\System32\wdflynik.ini
[2008/02/25 17:45:32 | 000,934,853 | -HS- | C] () -- C:\WINDOWS\System32\ihukixxc.ini
[2008/02/24 17:17:24 | 001,007,463 | -HS- | C] () -- C:\WINDOWS\System32\hnxwqwwv.ini
[2008/02/24 15:54:54 | 000,983,701 | -HS- | C] () -- C:\WINDOWS\System32\oswwjttn.ini
[2008/02/24 02:24:55 | 000,983,581 | -HS- | C] () -- C:\WINDOWS\System32\qykqgyyu.ini
[2008/02/23 16:38:07 | 000,983,461 | -HS- | C] () -- C:\WINDOWS\System32\vwwweloy.ini
[2008/02/23 14:50:24 | 000,983,368 | -HS- | C] () -- C:\WINDOWS\System32\cdogoesv.ini
[2008/02/22 18:50:24 | 000,983,775 | -HS- | C] () -- C:\WINDOWS\System32\sxpiedps.ini
[2008/02/22 18:29:43 | 001,004,140 | -HS- | C] () -- C:\WINDOWS\System32\mhxqtyyc.ini
[2008/02/20 20:23:29 | 001,069,720 | -HS- | C] () -- C:\WINDOWS\System32\tnhqrnri.ini
[2008/02/20 17:53:33 | 001,014,040 | -HS- | C] () -- C:\WINDOWS\System32\dmtjmkbc.ini
[2008/02/19 18:19:23 | 000,985,151 | -HS- | C] () -- C:\WINDOWS\System32\fdvyvocb.ini
[2008/02/18 17:59:17 | 001,042,595 | -HS- | C] () -- C:\WINDOWS\System32\cepumbfi.ini
[2008/02/17 10:49:24 | 001,035,193 | -HS- | C] () -- C:\WINDOWS\System32\bdwqogqj.ini
[2008/02/17 02:15:26 | 001,045,167 | -HS- | C] () -- C:\WINDOWS\System32\nyophkwm.ini
[2008/02/17 01:28:20 | 001,045,047 | -HS- | C] () -- C:\WINDOWS\System32\lkrovclj.ini
[2008/02/17 00:48:23 | 001,044,927 | -HS- | C] () -- C:\WINDOWS\System32\ftpuaubq.ini
[2008/02/16 18:54:58 | 001,044,801 | -HS- | C] () -- C:\WINDOWS\System32\cceeffgu.ini
[2008/02/16 12:47:58 | 001,061,158 | -HS- | C] () -- C:\WINDOWS\System32\grujckfk.ini
[2008/02/15 18:54:20 | 001,197,530 | -HS- | C] () -- C:\WINDOWS\System32\eyvudvaf.ini
[2008/02/14 17:57:10 | 001,123,247 | -HS- | C] () -- C:\WINDOWS\System32\bfyxecon.ini
[2008/02/13 18:46:33 | 001,116,793 | -HS- | C] () -- C:\WINDOWS\System32\rvphiftw.ini
[2008/02/13 17:41:18 | 001,183,101 | -HS- | C] () -- C:\WINDOWS\System32\imbmurui.ini
[2008/02/12 21:35:50 | 001,166,818 | -HS- | C] () -- C:\WINDOWS\System32\njhrqojm.ini
[2008/02/12 17:53:41 | 001,222,050 | -HS- | C] () -- C:\WINDOWS\System32\uuwjbfmm.ini
[2008/02/11 20:30:31 | 001,211,101 | -HS- | C] () -- C:\WINDOWS\System32\mnchrxtg.ini
[2008/02/11 18:00:47 | 001,221,257 | -HS- | C] () -- C:\WINDOWS\System32\eybmxdit.ini
[2008/02/10 14:20:00 | 001,218,806 | -HS- | C] () -- C:\WINDOWS\System32\gwnaxtqc.ini
[2008/02/10 13:50:20 | 001,218,650 | -HS- | C] () -- C:\WINDOWS\System32\jelirnkq.ini
[2008/02/10 13:02:32 | 001,218,530 | -HS- | C] () -- C:\WINDOWS\System32\brbkvaiw.ini
[2008/02/09 17:57:26 | 001,218,410 | -HS- | C] () -- C:\WINDOWS\System32\bqmpytoo.ini
[2008/02/09 03:32:52 | 001,218,389 | -HS- | C] () -- C:\WINDOWS\System32\fewwckjm.ini
[2008/02/08 17:54:25 | 001,221,986 | -HS- | C] () -- C:\WINDOWS\System32\rgxwjmky.ini
[2008/02/07 17:42:48 | 001,219,888 | -HS- | C] () -- C:\WINDOWS\System32\mapijvov.ini
[2008/02/06 20:57:49 | 001,200,161 | -HS- | C] () -- C:\WINDOWS\System32\xcggsfpt.ini
[2008/02/06 18:00:55 | 001,199,738 | -HS- | C] () -- C:\WINDOWS\System32\wyrtajwi.ini
[2008/02/05 22:08:55 | 001,133,610 | -HS- | C] () -- C:\WINDOWS\System32\jmkdqlnd.ini
[2008/02/05 21:20:43 | 001,133,568 | -HS- | C] () -- C:\WINDOWS\System32\csjukwgg.ini
[2008/02/05 19:43:58 | 001,135,893 | -HS- | C] () -- C:\WINDOWS\System32\qrpbxaok.ini
[2008/02/04 20:24:56 | 001,130,160 | -HS- | C] () -- C:\WINDOWS\System32\tvjjtjtm.ini
[2008/02/04 16:53:24 | 001,131,600 | -HS- | C] () -- C:\WINDOWS\System32\indqnlde.ini
[2008/02/04 08:39:01 | 001,131,825 | -HS- | C] () -- C:\WINDOWS\System32\ggmmoxpx.ini
[2008/02/04 07:02:18 | 001,131,615 | -HS- | C] () -- C:\WINDOWS\System32\iqesrqwp.ini
[2008/02/03 14:06:28 | 001,127,425 | -HS- | C] () -- C:\WINDOWS\System32\ieewitlt.ini
[2008/02/03 11:32:12 | 001,127,305 | -HS- | C] () -- C:\WINDOWS\System32\gqwyhnjk.ini
[2008/02/03 01:27:55 | 001,127,176 | -HS- | C] () -- C:\WINDOWS\System32\shyceeqv.ini
[2008/02/03 00:57:24 | 001,127,056 | -HS- | C] () -- C:\WINDOWS\System32\wseorjwy.ini
[2008/02/02 16:07:03 | 001,126,999 | -HS- | C] () -- C:\WINDOWS\System32\nvqckvib.ini
[2008/02/01 20:04:56 | 001,162,308 | -HS- | C] () -- C:\WINDOWS\System32\kfmxisia.ini
[2008/01/31 21:18:18 | 001,155,979 | -HS- | C] () -- C:\WINDOWS\System32\uetnwnaa.ini
[2008/01/31 20:30:24 | 001,155,841 | -HS- | C] () -- C:\WINDOWS\System32\pdyqrqhx.ini
[2008/01/31 17:39:24 | 001,168,115 | -HS- | C] () -- C:\WINDOWS\System32\kmhwybwm.ini
[2008/01/30 19:00:42 | 001,180,733 | -HS- | C] () -- C:\WINDOWS\System32\bpyexjiw.ini
[2008/01/29 20:50:45 | 001,167,221 | -HS- | C] () -- C:\WINDOWS\System32\tanhgrgf.ini
[2008/01/28 22:25:33 | 001,162,207 | -HS- | C] () -- C:\WINDOWS\System32\bhqmxblq.ini
[2008/01/28 21:37:22 | 001,162,339 | -HS- | C] () -- C:\WINDOWS\System32\xsblinxm.ini
[2008/01/28 20:55:25 | 001,162,225 | -HS- | C] () -- C:\WINDOWS\System32\klsfjpeo.ini
[2008/01/27 19:46:23 | 001,143,880 | -HS- | C] () -- C:\WINDOWS\System32\upawovfe.ini
[2008/01/27 18:48:52 | 001,143,594 | -HS- | C] () -- C:\WINDOWS\System32\fqbhpvnk.ini
[2008/01/27 15:09:09 | 001,143,472 | -HS- | C] () -- C:\WINDOWS\System32\xkdsehcg.ini
[2008/01/26 16:50:16 | 001,143,200 | -HS- | C] () -- C:\WINDOWS\System32\nlpcnabj.ini
[2008/01/26 12:03:06 | 001,142,692 | -HS- | C] () -- C:\WINDOWS\System32\mgpippsg.ini
[2008/01/25 17:33:56 | 000,976,342 | -HS- | C] () -- C:\WINDOWS\System32\pdglbkip.ini
[2008/01/24 19:26:50 | 000,994,174 | -HS- | C] () -- C:\WINDOWS\System32\bctutbjx.ini
[2008/01/23 18:13:23 | 001,022,387 | -HS- | C] () -- C:\WINDOWS\System32\nwgpxfto.ini
[2008/01/22 18:22:20 | 000,983,792 | -HS- | C] () -- C:\WINDOWS\System32\cefrseuk.ini
[2008/01/21 19:10:00 | 000,957,628 | -HS- | C] () -- C:\WINDOWS\System32\hsgfhxhc.ini
[2008/01/21 17:53:56 | 000,968,098 | -HS- | C] () -- C:\WINDOWS\System32\ffyvykek.ini
[2008/01/20 12:14:46 | 000,950,455 | -HS- | C] () -- C:\WINDOWS\System32\tlrepmbj.ini
[2008/01/19 12:58:10 | 000,952,502 | -HS- | C] () -- C:\WINDOWS\System32\bljqvnnj.ini
[2008/01/18 17:36:18 | 001,002,748 | -HS- | C] () -- C:\WINDOWS\System32\dwyafkbc.ini
[2008/01/17 18:17:41 | 001,070,167 | -HS- | C] () -- C:\WINDOWS\System32\plktyyww.ini
[2008/01/16 17:45:09 | 001,059,861 | -HS- | C] () -- C:\WINDOWS\System32\ovduukbq.ini
[2008/01/15 17:56:14 | 001,055,118 | -HS- | C] () -- C:\WINDOWS\System32\lrikucqt.ini
[2008/01/14 18:09:10 | 001,050,556 | -HS- | C] () -- C:\WINDOWS\System32\kcnxbkel.ini
[2008/01/13 15:01:22 | 001,053,893 | -HS- | C] () -- C:\WINDOWS\System32\trwhomhy.ini
[2008/01/13 12:18:26 | 001,053,809 | -HS- | C] () -- C:\WINDOWS\System32\kfinfudv.ini
[2008/01/12 13:13:33 | 001,053,675 | -HS- | C] () -- C:\WINDOWS\System32\hsllfxmj.ini
[2008/01/11 18:06:20 | 001,056,755 | -HS- | C] () -- C:\WINDOWS\System32\gunysesa.ini
[2008/01/10 17:55:54 | 001,061,177 | -HS- | C] () -- C:\WINDOWS\System32\wlflifnk.ini
[2008/01/09 18:08:08 | 001,046,237 | -HS- | C] () -- C:\WINDOWS\System32\rbtfpfuy.ini
[2008/01/09 17:54:30 | 001,046,030 | -HS- | C] () -- C:\WINDOWS\System32\mmfyfgfj.ini
[2008/01/08 17:49:48 | 001,050,877 | -HS- | C] () -- C:\WINDOWS\System32\fdtnaapw.ini
[2008/01/07 23:31:48 | 001,045,452 | -HS- | C] () -- C:\WINDOWS\System32\uefwpisr.ini
[2008/01/07 22:04:25 | 001,045,328 | -HS- | C] () -- C:\WINDOWS\System32\bijldhur.ini
[2008/01/07 00:43:52 | 001,045,451 | -HS- | C] () -- C:\WINDOWS\System32\noeabhpo.ini
[2008/01/06 17:51:25 | 001,045,358 | -HS- | C] () -- C:\WINDOWS\System32\kovtefdv.ini
[2008/01/06 13:08:26 | 001,045,189 | -HS- | C] () -- C:\WINDOWS\System32\qbiueiwy.ini
[2008/01/05 12:35:29 | 001,045,060 | -HS- | C] () -- C:\WINDOWS\System32\xeddffeb.ini
[2008/01/05 00:49:32 | 001,044,967 | -HS- | C] () -- C:\WINDOWS\System32\heobpqib.ini
[2008/01/04 17:51:18 | 001,044,820 | -HS- | C] () -- C:\WINDOWS\System32\dedasqjx.ini
[2008/01/03 17:42:52 | 001,044,700 | -HS- | C] () -- C:\WINDOWS\System32\nqvrggpl.ini
[2008/01/02 19:52:12 | 001,032,241 | -HS- | C] () -- C:\WINDOWS\System32\htlmhlly.ini
[2008/01/02 18:11:43 | 001,032,067 | -HS- | C] () -- C:\WINDOWS\System32\wdfrwtfh.ini
[2008/01/01 19:20:51 | 001,031,706 | -HS- | C] () -- C:\WINDOWS\System32\cixssgfp.ini
[2007/12/31 22:35:49 | 001,031,559 | -HS- | C] () -- C:\WINDOWS\System32\seqkkviv.ini
[2007/12/31 14:22:53 | 001,031,439 | -HS- | C] () -- C:\WINDOWS\System32\qqhvmpee.ini
[2007/12/30 14:48:47 | 001,031,401 | -HS- | C] () -- C:\WINDOWS\System32\sbcqvmlu.ini
[2007/12/30 11:11:28 | 001,031,235 | -HS- | C] () -- C:\WINDOWS\System32\vaoascpm.ini
[2007/12/24 11:13:28 | 001,311,078 | -HS- | C] () -- C:\WINDOWS\System32\jeyaqwqo.ini
[2007/12/22 08:39:55 | 001,313,151 | -HS- | C] () -- C:\WINDOWS\System32\naowmnga.ini
[2007/12/21 18:25:57 | 001,376,077 | -HS- | C] () -- C:\WINDOWS\System32\eyiddlhl.ini
[2007/12/21 18:07:10 | 001,420,193 | -HS- | C] () -- C:\WINDOWS\System32\lnogyalm.ini
[2007/12/20 18:08:10 | 001,405,880 | -HS- | C] () -- C:\WINDOWS\System32\bwhmbsil.ini
[2007/12/19 21:08:00 | 001,399,909 | -HS- | C] () -- C:\WINDOWS\System32\dttcfpje.ini
[2007/12/18 21:16:26 | 001,366,693 | -HS- | C] () -- C:\WINDOWS\System32\rhfvhuxl.ini
[2007/12/17 04:59:15 | 001,337,259 | -HS- | C] () -- C:\WINDOWS\System32\bqycbnom.ini
[2007/12/16 10:44:24 | 001,338,199 | -HS- | C] () -- C:\WINDOWS\System32\vrxteeor.ini
[2007/12/14 22:59:26 | 001,341,998 | -HS- | C] () -- C:\WINDOWS\System32\csrdpwii.ini
[2007/12/13 18:10:50 | 001,328,986 | -HS- | C] () -- C:\WINDOWS\System32\njkfmbbx.ini
[2007/12/12 22:59:50 | 000,000,263 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/12/12 21:01:29 | 001,283,621 | -HS- | C] () -- C:\WINDOWS\System32\lysqbuso.ini
[2007/12/12 18:17:56 | 001,293,381 | -HS- | C] () -- C:\WINDOWS\System32\tjjmamum.ini
[2007/12/10 22:19:27 | 001,345,120 | -HS- | C] () -- C:\WINDOWS\System32\wurjvehj.ini
[2007/12/10 21:39:50 | 001,200,796 | -HS- | C] () -- C:\WINDOWS\System32\ppoudlia.ini
[2007/12/07 18:09:23 | 001,252,634 | -HS- | C] () -- C:\WINDOWS\System32\qquyhxxe.ini
[2007/12/06 15:22:48 | 001,183,941 | -HS- | C] () -- C:\WINDOWS\System32\fvobyjus.ini
[2007/12/05 17:40:50 | 001,153,175 | -HS- | C] () -- C:\WINDOWS\System32\lnycpjuh.ini
[2007/12/04 22:59:06 | 001,112,234 | -HS- | C] () -- C:\WINDOWS\System32\knekwedl.ini
[2007/12/04 19:45:52 | 000,999,358 | -HS- | C] () -- C:\WINDOWS\System32\sngwodtn.ini
[2007/12/03 21:28:03 | 000,999,298 | -HS- | C] () -- C:\WINDOWS\System32\atodqijj.ini
[2007/12/03 18:45:43 | 001,000,642 | -HS- | C] () -- C:\WINDOWS\System32\evikmetg.ini
[2007/12/02 03:34:08 | 001,002,998 | -HS- | C] () -- C:\WINDOWS\System32\dthamllm.ini
[2007/11/29 17:59:50 | 000,922,347 | -HS- | C] () -- C:\WINDOWS\System32\whnsdnpk.ini
[2007/11/24 11:08:34 | 001,092,095 | -HS- | C] () -- C:\WINDOWS\System32\dlvmrhmo.ini
[2007/11/22 17:19:59 | 000,793,074 | -HS- | C] () -- C:\WINDOWS\System32\dtjuodqi.ini
[2007/11/21 20:38:52 | 000,789,481 | -HS- | C] () -- C:\WINDOWS\System32\sspijtjd.ini
[2007/11/21 19:38:51 | 000,843,027 | -HS- | C] () -- C:\WINDOWS\System32\rcoopbnd.ini
[2007/11/20 20:34:41 | 000,689,502 | -HS- | C] () -- C:\WINDOWS\System32\wtpwaghf.ini
[2007/11/18 12:52:57 | 000,678,085 | -HS- | C] () -- C:\WINDOWS\System32\fuyxqmkr.ini
[2007/11/17 12:50:06 | 000,677,920 | -HS- | C] () -- C:\WINDOWS\System32\egcrpvho.ini
[2007/11/17 09:19:13 | 001,239,529 | -HS- | C] () -- C:\WINDOWS\System32\kjswqhjx.ini
[2007/11/15 17:54:13 | 001,239,529 | -HS- | C] () -- C:\WINDOWS\System32\frtctivj.ini
[2007/11/12 17:47:19 | 001,306,718 | -HS- | C] () -- C:\WINDOWS\System32\vtfeswjc.ini
[2007/11/11 21:45:11 | 001,216,392 | -HS- | C] () -- C:\WINDOWS\System32\wmiwmeva.ini
[2007/11/10 21:42:11 | 001,216,263 | -HS- | C] () -- C:\WINDOWS\System32\qqfsrtaj.ini
[2007/11/09 21:42:13 | 001,218,528 | -HS- | C] () -- C:\WINDOWS\System32\wgyobblk.ini
[2007/11/08 18:55:59 | 001,210,366 | -HS- | C] () -- C:\WINDOWS\System32\nhxfkdix.ini
[2007/11/06 19:21:14 | 001,212,057 | -HS- | C] () -- C:\WINDOWS\System32\uhkepgjn.ini
[2007/10/29 16:58:18 | 001,199,834 | -HS- | C] () -- C:\WINDOWS\System32\bvdctdpp.ini
[2007/10/25 20:49:14 | 001,199,660 | -HS- | C] () -- C:\WINDOWS\System32\unwycxep.ini
[2007/10/25 18:02:12 | 000,693,481 | -HS- | C] () -- C:\WINDOWS\System32\taowgixo.ini
[2007/10/22 17:18:05 | 000,693,730 | -HS- | C] () -- C:\WINDOWS\System32\ofoovnmx.ini
[2007/10/22 17:00:33 | 000,693,610 | -HS- | C] () -- C:\WINDOWS\System32\cwifjwkd.ini
[2007/10/22 16:54:41 | 000,000,246 | ---- | C] () -- C:\Program Files\Common Files\qucav655
[2007/10/21 20:36:52 | 000,693,490 | -HS- | C] () -- C:\WINDOWS\System32\uaefkwyb.ini
[2007/10/21 20:22:31 | 000,006,520 | -HS- | C] () -- C:\WINDOWS\System32\mpqss.ini
[2007/10/20 14:42:45 | 000,230,137 | -HS- | C] () -- C:\WINDOWS\System32\mpqss.ini2
[2007/09/11 21:35:09 | 000,000,198 | ---- | C] () -- C:\Documents and Settings\ISAIAH\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2007/09/09 01:32:40 | 000,000,010 | ---- | C] () -- C:\Program Files\.autoreg
[2007/08/30 17:11:22 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2007/08/30 17:11:06 | 000,001,668 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI
[2007/08/09 18:45:17 | 000,122,368 | ---- | C] () -- C:\Documents and Settings\ISAIAH\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/06/29 15:03:51 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\DigiPlatformSupport.dll
[2007/06/29 14:46:52 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2007/06/28 17:52:56 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\ISAIAH\Local Settings\Application Data\fusioncache.dat
[2006/12/05 17:00:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ernel32.dll
[2006/07/13 19:03:04 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/07/13 18:57:07 | 000,000,126 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/07/13 18:27:02 | 000,000,387 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/11/09 23:56:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/08/16 02:37:24 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 02:33:38 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/08/16 02:18:42 | 000,188,928 | ---- | C] () -- C:\WINDOWS\elodoxirakipe.dll
[2005/08/05 12:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[1997/06/13 18:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== Custom Scans ==========
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/08/16 02:42:12 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/04/30 12:43:32 | 000,078,336 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\DLBKPP5C.DLL
[2008/07/06 05:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 03:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2002/05/14 15:50:34 | 000,011,264 | ---- | M] (BVRP Software) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint2000.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/06/02 18:59:32 | 000,019,949 | ---- | M] () -- C:\WINDOWS\dipem.scr
[2008/07/06 10:19:23 | 000,019,441 | ---- | M] () -- C:\WINDOWS\vovexyw.scr
< %systemroot%\*._sy >
[2008/07/03 08:09:17 | 000,018,355 | ---- | M] () -- C:\WINDOWS\tari._sy
[2008/06/13 00:06:19 | 000,014,304 | ---- | M] () -- C:\WINDOWS\wuba._sy
[2008/06/10 11:18:13 | 000,016,180 | ---- | M] () -- C:\WINDOWS\ynexavebe._sy
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2007/09/09 01:32:40 | 000,000,010 | ---- | M] () -- C:\Program Files\.autoreg
< %APPDATA%\Update\*.* >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/08/16 02:43:10 | 000,000,294 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2008/06/23 14:51:08 | 000,017,820 | ---- | M] () -- C:\WINDOWS\system32\rama.db
[2008/06/02 18:59:32 | 000,014,214 | ---- | M] () -- C:\WINDOWS\system32\ubyrybid.db
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/06/28 17:53:03 | 000,000,170 | -HS- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/16 02:50:28 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/02/13 14:52:59 | 002,257,408 | ---- | M] () -- C:\Documents and Settings\ISAIAH\Desktop\LeagueofLegends.exe
[2010/10/18 20:34:12 | 030,164,216 | ---- | M] (Lime Wire LLC) -- C:\Documents and Settings\ISAIAH\Desktop\LimeWireWin.exe
< %PROGRAMFILES%\Common Files\*.* >
[2008/06/02 18:59:32 | 000,018,062 | ---- | M] () -- C:\Program Files\Common Files\aticure.vbs
[2008/06/10 11:18:14 | 000,016,345 | ---- | M] () -- C:\Program Files\Common Files\awudigyby.dll
[2008/06/10 11:18:13 | 000,018,698 | ---- | M] () -- C:\Program Files\Common Files\budedawyv.dat
[2008/06/10 11:18:14 | 000,012,111 | ---- | M] () -- C:\Program Files\Common Files\edusysujez.inf
[2008/06/02 18:59:32 | 000,013,094 | ---- | M] () -- C:\Program Files\Common Files\mutetidid.sys
[2008/06/02 18:59:32 | 000,014,650 | ---- | M] () -- C:\Program Files\Common Files\qexykidu.sys
[2007/10/22 16:54:58 | 000,000,246 | ---- | M] () -- C:\Program Files\Common Files\qucav655
[2008/06/13 00:06:19 | 000,010,621 | ---- | M] () -- C:\Program Files\Common Files\rejupyvys.ban
[2008/06/10 11:18:13 | 000,014,898 | ---- | M] () -- C:\Program Files\Common Files\uvyvany.reg
[2008/06/02 18:59:32 | 000,016,029 | ---- | M] () -- C:\Program Files\Common Files\widar.bat
[2008/06/13 00:06:19 | 000,016,908 | ---- | M] () -- C:\Program Files\Common Files\ycawumyv._sy
[2008/06/13 00:06:19 | 000,013,664 | ---- | M] () -- C:\Program Files\Common Files\ygyjefon.bat
[2008/06/02 18:59:32 | 000,017,098 | ---- | M] () -- C:\Program Files\Common Files\ynyro.scr
[2008/06/13 00:06:19 | 000,014,240 | ---- | M] () -- C:\Program Files\Common Files\yzyver.dl
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
[2007/10/18 18:02:04 | 000,000,008 | ---- | M] () -- C:\WINDOWS\java\rabgiab.dat
[2007/10/18 18:02:07 | 000,000,008 | ---- | M] () -- C:\WINDOWS\java\rabgibb.dat
[2007/10/18 18:02:07 | 000,000,008 | ---- | M] () -- C:\WINDOWS\java\rabgicb.dat
[2007/10/18 18:02:07 | 000,000,046 | ---- | M] () -- C:\WINDOWS\java\rabgil.dat
[2007/10/15 18:46:44 | 000,000,008 | ---- | M] () -- C:\WINDOWS\java\rabgip1b.dat
[2007/10/18 18:02:07 | 000,001,150 | ---- | M] () -- C:\WINDOWS\java\rabgis.dat
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
[2008/12/16 21:40:29 | 007,518,240 | ---- | M] (Mozilla) -- C:\Documents and Settings\ISAIAH\My Documents\Firefox Setup 3.0.5.exe
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2004/08/10 03:00:00 | 000,000,791 | ---- | M] () -- C:\WINDOWS\addins\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2010/04/09 15:35:04 | 000,185,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2010/04/09 15:35:04 | 000,307,672 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2010/04/09 15:35:06 | 000,242,136 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2007/06/28 17:53:02 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\ISAIAH\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2007/12/29 21:37:06 | 000,000,418 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2005/07/25 21:39:44 | 001,267,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\comsvcs.dll
[2010/04/16 08:20:18 | 000,357,888 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2010/04/16 08:20:18 | 000,205,312 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.exe /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005/08/16 02:27:08 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2005/08/16 02:27:08 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2005/08/16 02:27:08 | 000,876,544 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.sys >
[2004/08/10 03:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2005/02/01 17:18:38 | 000,017,992 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\bcm42rly.sys
[2004/08/10 03:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2004/06/09 08:29:56 | 000,006,977 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\DDMI2.sys
[2005/03/13 14:54:00 | 000,006,656 | ---- | M] (GTek Technologies Ltd.) -- C:\WINDOWS\system32\DLPT2.sys
[2005/02/08 10:37:52 | 000,007,626 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GPCIEnum.sys
[2004/06/15 14:55:56 | 000,007,882 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GTKCMOS.sys
[2003/09/25 21:15:32 | 000,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\system32\GTNDIS5.sys
[2004/08/10 03:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2004/08/10 03:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2004/08/10 03:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2005/01/01 02:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) -- C:\WINDOWS\system32\npptNT2.sys
[2004/08/10 03:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2004/08/10 03:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2004/08/10 03:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2004/08/10 03:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2004/08/10 03:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2004/08/10 03:00:00 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2004/08/10 03:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2004/08/10 03:00:00 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2004/08/10 03:00:00 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2004/08/10 03:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2008/06/13 00:06:19 | 000,016,384 | ---- | M] () -- C:\WINDOWS\system32\olylopu.sys
[2005/10/17 18:50:06 | 000,245,376 | ---- | M] (Ralink Technology Inc.) -- C:\WINDOWS\system32\rt2500usb.sys
[2004/08/10 03:00:00 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2007/03/08 06:47:48 | 001,843,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k(2).sys
[2007/03/08 06:47:48 | 001,843,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k(3).sys
[2010/05/01 22:56:34 | 001,850,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[2004/01/07 16:04:00 | 000,339,488 | ---- | M] (Cisco-Linksys, LLC.) -- C:\WINDOWS\system32\WUSB20XP.sys
[2004/04/23 21:43:00 | 000,374,752 | ---- | M] (Cisco-Linksys, LLC.) -- C:\WINDOWS\system32\WUSBGXP.sys
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.dll >
[2005/08/03 18:08:34 | 000,040,960 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2erec.dll
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2003/04/30 12:43:32 | 000,078,336 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\DLBKPP5C.DLL
[2008/07/06 05:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2002/05/14 15:50:34 | 000,011,264 | ---- | M] (BVRP Software) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint2000.dll
< %SYSTEMDRIVE%\*.* >
[2005/08/16 02:43:04 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2007/06/28 17:52:43 | 000,000,209 | -HS- | M] () -- C:\BoOT.INi
[2005/08/16 02:43:04 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2006/07/13 18:30:42 | 000,007,046 | RH-- | M] () -- C:\dell.sdr
[2011/02/13 15:49:42 | 2145,554,432 | -HS- | M] () -- C:\hiberfil.sys
[2007/06/29 15:05:45 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2005/08/16 02:43:04 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2006/07/13 18:51:14 | 000,000,838 | -H-- | M] () -- C:\IPH.PH
[2005/08/16 02:43:04 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2004/08/10 03:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2004/08/10 03:00:00 | 000,250,032 | RHS- | M] () -- C:\ntldr
[2011/02/13 15:49:42 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2007/06/29 14:43:40 | 000,104,125 | ---- | M] () -- C:\pc-decrap-reg.txt
[2007/06/29 14:49:23 | 000,068,038 | ---- | M] () -- C:\pc-decrapifier-msi.log
[2007/06/29 14:52:12 | 000,000,858 | ---- | M] () -- C:\pc-decrapifier.log
[2009/05/18 19:05:42 | 000,000,168 | ---- | M] () -- C:\setupfax.log
[2006/07/13 18:51:20 | 000,000,087 | ---- | M] () -- C:\SystemInfo.ini
[2007/09/04 20:47:08 | 000,020,480 | ---- | M] () -- C:\test.pcm
[2010/07/19 15:35:05 | 000,000,150 | ---- | M] () -- C:\zrpt.xml
< %PROGRAMFILES%\*. >
[2009/06/10 13:01:43 | 000,000,000 | ---D | M] -- C:\Program Files\ABBYY FineReader 5.0 Sprint
[2009/06/10 13:01:40 | 000,000,000 | ---D | M] -- C:\Program Files\ABBYY FineReader 6.0
[2009/05/17 20:07:07 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2010/01/06 18:18:12 | 000,000,000 | ---D | M] -- C:\Program Files\AGEIA Technologies
[2008/12/25 09:13:39 | 000,000,000 | ---D | M] -- C:\Program Files\ArcSoft
[2010/10/22 01:02:10 | 000,000,000 | ---D | M] -- C:\Program Files\Ask.com
[2006/07/13 18:48:10 | 000,000,000 | ---D | M] -- C:\Program Files\ATI Technologies
[2006/07/13 18:57:28 | 000,000,000 | ---D | M] -- C:\Program Files\BAE
[2007/07/29 13:21:30 | 000,000,000 | ---D | M] -- C:\Program Files\BFD
[2007/07/29 13:19:27 | 000,000,000 | ---D | M] -- C:\Program Files\BFDXFL
[2010/08/13 17:48:14 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2005/08/16 02:38:36 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2006/07/13 18:32:42 | 000,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2006/07/13 18:54:43 | 000,000,000 | ---D | M] -- C:\Program Files\Corel Corporation
[2007/06/29 14:44:37 | 000,000,000 | ---D | M] -- C:\Program Files\Dell
[2009/05/18 19:04:11 | 000,000,000 | ---D | M] -- C:\Program Files\Dell A920
[2009/06/10 13:01:27 | 000,000,000 | ---D | M] -- C:\Program Files\Dell AIO Printer A920
[2006/07/13 18:52:07 | 000,000,000 | ---D | M] -- C:\Program Files\Dell Support
[2010/04/14 16:17:22 | 000,000,000 | ---D | M] -- C:\Program Files\Diablo II
[2007/06/29 15:27:34 | 000,000,000 | ---D | M] -- C:\Program Files\DIFX
[2008/02/04 08:16:33 | 000,000,000 | ---D | M] -- C:\Program Files\Digidesign
[2006/07/13 18:48:50 | 000,000,000 | ---D | M] -- C:\Program Files\Digital Line Detect
[2005/08/16 18:54:50 | 000,000,000 | ---D | M] -- C:\Program Files\DIGStream
[2009/12/16 23:50:29 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2010/05/19 18:18:23 | 000,000,000 | ---D | M] -- C:\Program Files\DOSBox-0.72
[2008/06/09 20:09:04 | 000,000,000 | ---D | M] -- C:\Program Files\EndItAll
[2005/08/16 18:51:50 | 000,000,000 | ---D | M] -- C:\Program Files\EnglishOtto
[2005/08/16 18:54:50 | 000,000,000 | ---D | M] -- C:\Program Files\ESPNMotion
[2009/06/10 13:01:39 | 000,000,000 | ---D | M] -- C:\Program Files\FaxTools
[2009/12/08 21:33:56 | 000,000,000 | ---D | M] -- C:\Program Files\Firefly Studios
[2007/07/29 13:20:33 | 000,000,000 | ---D | M] -- C:\Program Files\FXpansion
[2005/08/16 18:54:44 | 000,000,000 | ---D | M] -- C:\Program Files\GemMaster
[2010/05/19 18:26:08 | 000,000,000 | ---D | M] -- C:\Program Files\GOG.com
[2008/02/16 19:29:29 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2010/02/15 13:35:26 | 000,000,000 | ---D | M] -- C:\Program Files\Guitar Pro 5
[2011/02/13 15:29:59 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2006/07/13 18:48:33 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2006/07/13 18:48:29 | 000,000,000 | ---D | M] -- C:\Program Files\InterActual
[2007/06/29 15:06:37 | 000,000,000 | ---D | M] -- C:\Program Files\InterLok
[2010/06/28 00:12:26 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2009/03/09 16:51:27 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2006/07/13 18:51:12 | 000,000,000 | ---D | M] -- C:\Program Files\Learn2.com
[2010/10/18 20:36:02 | 000,000,000 | ---D | M] -- C:\Program Files\LimeWire
[2008/06/03 18:43:00 | 000,000,000 | ---D | M] -- C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor
[2010/08/16 10:55:08 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/08 15:08:11 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee
[2010/05/08 15:08:28 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee.com
[2008/08/13 01:18:22 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/04/26 16:15:16 | 000,000,000 | ---D | M] -- C:\Program Files\Microids
[2005/08/16 02:43:46 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2010/03/12 22:27:21 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Games
[2006/07/13 18:48:44 | 000,000,000 | ---D | M] -- C:\Program Files\Modem Helper
[2010/03/13 01:03:04 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2011/02/13 15:52:59 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009/10/24 00:01:47 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2007/08/08 10:46:43 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2005/08/16 02:37:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2008/12/26 18:55:34 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2007/08/31 19:54:41 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 6.0
[2007/06/29 14:48:03 | 000,000,000 | ---D | M] -- C:\Program Files\MUSICMATCH
[2007/07/08 12:08:02 | 000,000,000 | ---D | M] -- C:\Program Files\Native Instruments
[2005/08/16 02:40:14 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2006/07/13 18:48:56 | 000,000,000 | ---D | M] -- C:\Program Files\NetWaiting
[2008/12/25 09:09:28 | 000,000,000 | ---D | M] -- C:\Program Files\Nikon
[2009/06/10 13:01:21 | 000,000,000 | ---D | M] -- C:\Program Files\NOS
[2005/08/16 02:38:24 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010/05/15 00:00:40 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2011/02/13 14:53:39 | 000,000,000 | ---D | M] -- C:\Program Files\Pando Networks
[2008/06/12 23:55:03 | 000,000,000 | ---D | M] -- C:\Program Files\PCPitstop
[2008/02/29 19:15:40 | 000,000,000 | ---D | M] -- C:\Program Files\Picasa2
[2011/02/03 22:38:19 | 000,000,000 | ---D | M] -- C:\Program Files\PowerISO
[2007/06/30 16:28:19 | 000,000,000 | ---D | M] -- C:\Program Files\Propellerhead
[2008/12/25 09:07:47 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2006/07/13 18:50:56 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2009/10/24 00:01:39 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2005/08/16 18:58:50 | 000,000,000 | ---D | M] -- C:\Program Files\RGB
[2007/06/29 14:49:14 | 000,000,000 | ---D | M] -- C:\Program Files\Roxio
[2006/07/13 18:57:28 | 000,000,000 | ---D | M] -- C:\Program Files\SearchAssist
[2006/07/13 18:45:39 | 000,000,000 | ---D | M] -- C:\Program Files\Sigmatel
[2010/04/14 23:46:55 | 000,000,000 | ---D | M] -- C:\Program Files\softnyx
[2006/07/13 18:57:26 | 000,000,000 | ---D | M] -- C:\Program Files\Sonic
[2005/08/16 02:50:18 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010/07/20 13:44:34 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2006/07/13 18:51:11 | 000,000,000 | ---D | M] -- C:\Program Files\Viewpoint
[2007/07/29 13:20:36 | 000,000,000 | ---D | M] -- C:\Program Files\vstPlugins
[2007/06/29 16:54:19 | 000,000,000 | ---D | M] -- C:\Program Files\Waves
[2006/07/13 18:52:16 | 000,000,000 | ---D | M] -- C:\Program Files\WebCyberCoach
[2008/02/16 19:28:53 | 000,000,000 | ---D | M] -- C:\Program Files\Western Digital
[2008/02/16 19:21:56 | 000,000,000 | ---D | M] -- C:\Program Files\Western Digital Technologies
[2006/07/13 18:52:25 | 000,000,000 | ---D | M] -- C:\Program Files\WildTangent
[2007/12/29 21:36:52 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2008/07/13 17:25:21 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2005/08/16 02:37:22 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2005/08/16 02:37:56 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Plus
[2005/08/16 02:40:46 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2005/08/16 02:43:46 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
< %appdata%\*.* >
[2008/06/02 18:59:32 | 000,010,463 | ---- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\aponaqyno._sy
[2005/08/16 02:33:26 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\desktop.ini
[2008/12/25 09:08:37 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\Flowers
[2008/08/31 11:28:05 | 000,000,198 | ---- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2008/06/02 18:59:32 | 000,019,404 | ---- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\qanekufod.com
[2008/06/10 11:18:13 | 000,013,654 | ---- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\qurolesa.bat
[2008/06/10 11:18:13 | 000,017,878 | ---- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\ratuda._sy
[2008/06/10 11:18:13 | 000,014,210 | ---- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\ujedoka.sys
[2008/06/13 00:06:19 | 000,010,012 | ---- | M] () -- C:\Documents and Settings\ISAIAH\Application Data\yrig.db
< MD5 for: AGP440.SYS >
[2004/08/10 03:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
[2004/08/10 03:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\agp440.sys
[2004/08/03 21:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2004/08/10 03:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
[2004/08/10 03:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\atapi.sys
[2004/08/03 20:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004/08/03 20:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 20:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys
< MD5 for: DISK.SYS >
[2004/08/10 03:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\i386\sp2.cab:disk.sys
[2004/08/10 03:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2004/08/10 03:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\system32\drivers\disk.sys
[2008/04/13 11:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\disk.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\eventlog.dll
[2004/08/10 03:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: IASTOR.SYS >
[2005/06/17 03:33:40 | 000,872,064 | ---- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 -- C:\drivers\storage\sata\onboard\iastor.sys
[2005/06/17 03:33:40 | 000,872,064 | ---- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 -- C:\WINDOWS\system32\drivers\iaStor.sys
< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\netlogon.dll
[2009/02/06 11:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$NtUninstallKB975467$\netlogon.dll
[2009/02/06 11:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2009/02/06 11:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/10 03:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtUninstallKB968389$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/10 03:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\scecli.dll
< MD5 for: USBSTOR.SYS >
[2004/08/10 03:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\i386\sp2.cab:usbstor.sys
[2004/08/10 03:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2004/08/03 22:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\system32\dllcache\usbstor.sys
[2004/08/03 22:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\system32\drivers\USBSTOR.SYS
[2008/04/13 11:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-17 03:11:47
========== Files - Unicode (All) ==========
[2007/12/30 21:21:59 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?dobe) -- C:\WINDOWS\System32\Αdobe
[2007/09/12 18:28:21 | 000,000,000 | ---D | M](C:\WINDOWS\??curity) -- C:\WINDOWS\ѕеcurity
[2007/09/09 01:21:50 | 000,000,000 | ---D | M](C:\WINDOWS\?racle) -- C:\WINDOWS\Оracle
[2007/09/09 01:21:50 | 000,000,000 | ---D | C](C:\WINDOWS\?racle) -- C:\WINDOWS\Оracle
[2007/09/02 11:12:36 | 000,000,000 | ---D | C](C:\WINDOWS\??curity) -- C:\WINDOWS\ѕеcurity
[2007/09/02 11:11:16 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?dobe) -- C:\WINDOWS\System32\Αdobe
========== Alternate Data Streams ==========
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\win.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\tsiwinfile.dat:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\wow32.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\wbcache.deu:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\unicode.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\tssoft32.acm:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\stdole2.tlb:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\sorttbls.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\sortkey.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\sl_anet.acm:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\qtutv.ini2:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\OEMLOGO.BMP:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\oembios.sig:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\oembios.dat:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\oembios.bin:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\ntimage.gif:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MSINET.oca:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\msgsm32.acm:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\msg723.acm:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\msg711.acm:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\msadp32.acm:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\locale.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\l3codecp.acm:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\l_intl.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\imaadp32.acm:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\geo.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\FNTCACHE.DAT:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\tdpipe.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\tdi.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\pcmcia.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\parvdm.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\hidparse.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\hidclass.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\fs_rec.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\dxgthk.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\dxg.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\dxapi.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\bridge.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\bcm42rly.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\atmuni.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\atmlane.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\atmepvc.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\ativvpxx.vp:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\ativckxx.vp:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\ativcaxx.vp:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\ativcaxx.cpa:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\amdk6.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\DRIVERS\amdagp.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\DRIVERS\alim1541.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\DRIVERS\agpCPQ.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\DRIVERS\agp440.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\1028_Dell_XPS_DXPO51.mrk:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\ctype.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\comsvcs.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\c_950.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\c_949.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\c_936.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\c_932.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\c_28592.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\c_28591.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\c_1253.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\c_1251.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\c_1250.nls:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\atiicdxx.dat:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\alrsvc.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\12520850.cpx:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\12520437.cpx:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\spupdsvc.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\nsreg.dat:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\KB941569.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\KB939683.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\KB936782.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\KB905589.log:KAVICHS